Home / Alt manpages / wpa_supplicant(8)

  • wpa_supplicant(8)
  • Admin command
  • linux

Connect a Linux Wi-Fi Interface with wpa_supplicant

You will configure one WPA-Personal network, test the connection in the foreground, and then start wpa_supplicant as a background daemon. This guide uses wpa_supplicant 2.10 from Ubuntu package wpasupplicant version 2:2.10-21ubuntu0.4. Allow about 15 minutes, plus time to find the correct wireless interface name.

The commands assume Linux, an available Wi-Fi device, a loaded driver, and permission to change network state. The installed manual identifies nl80211 as the preferred Linux driver. This guide changes the wireless connection and writes a file containing a network credential, so read the warning in step 2 before copying anything.

1. Find the interface and check the program

Run these read-only checks as your normal user:

$ command -v wpa_supplicant
/usr/sbin/wpa_supplicant
$ wpa_supplicant -v
wpa_supplicant v2.10
$ ip link show

Use the name of the wireless interface from ip link show, commonly something such as wlan0 or wlp2s0. Replace wlan0 in every command below if yours is different. The interface must already exist and be enabled: the daemon exits if the device or its driver is not available.

Checkpoint

You have a real interface name and wpa_supplicant -v reports the installed version. Do not guess the name from an old configuration.

2. Create a private configuration

Use a root-owned file when the machine has more than one user. The configuration can contain a plain-text passphrase, certificate passwords, or other authentication material. Do not put a real password in shell history, a ticket, or a public repository. Start with an editor:

$ sudoedit /etc/wpa_supplicant.conf

For a WPA-Personal network, enter this small configuration and replace both placeholder values:

ctrl_interface=DIR=/var/run/wpa_supplicant GROUP=netdev
network={
    ssid="EXAMPLE_SSID"
    key_mgmt=WPA-PSK
    psk="EXAMPLE_WIFI_PASSPHRASE"
}

The ctrl_interface line creates a Unix control socket under /var/run/wpa_supplicant and permits the named group to use it. Only choose netdev if that group exists and its membership is appropriate on your system. Otherwise omit the GROUP=... part and keep control access restricted.

Protect the file after saving:

$ sudo chown root:root /etc/wpa_supplicant.conf
$ sudo chmod 600 /etc/wpa_supplicant.conf
$ sudo ls -l /etc/wpa_supplicant.conf
-rw------- 1 root root ... /etc/wpa_supplicant.conf

For a less exposed file, generate a hashed PSK instead. The installed wpa_passphrase command accepts the SSID and reads the passphrase from standard input:

$ printf '%s\n' 'EXAMPLE_WIFI_PASSPHRASE' | wpa_passphrase 'EXAMPLE_SSID'
network={
    ssid="EXAMPLE_SSID"
    #psk="EXAMPLE_WIFI_PASSPHRASE"
    psk=GENERATED_HEX_PSK
}

Copy the generated network block without the commented plain-text psk line into the protected configuration. A hashed PSK still grants network access if the file is stolen, so file permissions remain necessary.

3. Test in the foreground

Stop any existing network manager or supplicant instance that owns this interface before testing. Do not kill every wpa_supplicant process on a multi-interface host. Then run this command as root so it can open the device and configure the connection:

$ sudo wpa_supplicant -Dnl80211 -iwlan0 -c/etc/wpa_supplicant.conf -d

Foreground mode keeps diagnostic output in the terminal. A successful run continues waiting while it manages the interface; messages should show scanning, association, and WPA key negotiation. Leave it running and open a second terminal for the next check. Press Ctrl-C to stop this test instance.

If it exits immediately, rerun with a second -d for more detail:

$ sudo wpa_supplicant -Dnl80211 -iwlan0 -c/etc/wpa_supplicant.conf -dd

Common traps are a misspelled interface, a device that is blocked or down, a wrong SSID or passphrase, and starting a second supplicant on the same interface. Keep the first error message that identifies the failure. Do not add -K while investigating: that option includes keys and passwords in debug output.

4. Verify association before requesting an address

In another terminal, inspect the link without changing it:

$ iw dev wlan0 link
Connected to AA:BB:CC:DD:EE:FF (on wlan0)
	SSID: EXAMPLE_SSID
	...
$ ip addr show dev wlan0

The exact signal and bitrate lines vary. The useful result is a Connected to line with the expected SSID. wpa_supplicant handles the wireless authentication and encryption; it does not replace the higher-level DHCP or address-management step. Use the network manager or DHCP tooling already responsible for this host after association is confirmed.

Checkpoint

The wireless link is associated, and the interface has an address if your normal network setup has run. If association is good but there is no address, diagnose DHCP separately rather than changing WPA settings at random.

5. Run it in the background

Once the foreground test works, stop it with Ctrl-C and start one background instance:

$ sudo wpa_supplicant -B -Dnl80211 -iwlan0 -c/etc/wpa_supplicant.conf
Successfully initialized wpa_supplicant

-B makes the daemon fork into the background. The daemon's control socket is useful only if the configuration enabled ctrl_interface. If a distribution service or network manager normally owns the interface, configure that integration instead of launching a competing manual instance.

Configuration changes can be reloaded with a hangup signal, or through wpa_cli reconfigure when the control socket is available:

$ sudo kill -HUP "$(pgrep -xo wpa_supplicant)"
$ sudo wpa_cli -i wlan0 reconfigure

Use one reload method, not both. The first command targets the oldest matching process and is only safe when you have confirmed that it is the instance for this interface. Prefer the service manager's reload operation on a managed system. If you need to undo this manual start, stop the specific instance through its service integration or control interface; do not use an unqualified pkill wpa_supplicant on a host with other wireless interfaces.

6. Add enterprise authentication only with its trust details

WPA-Enterprise is a different configuration, not a stronger version of the PSK block. The installed configuration manual documents, among others, EAP-TLS, PEAP and TTLS. An EAP-TLS network needs an identity, a CA certificate, a client certificate and its matching private key:

network={
    ssid="EXAMPLE_CORPORATE_SSID"
    key_mgmt=WPA-EAP
    eap=TLS
    identity="[email protected]"
    ca_cert="/etc/wpa_supplicant/certs/ca.pem"
    client_cert="/etc/wpa_supplicant/certs/user.pem"
    private_key="/etc/wpa_supplicant/certs/user.prv"
    private_key_passwd="EXAMPLE_KEY_PASSWORD"
}

Use absolute certificate paths because the daemon may change its working directory in background mode. Confirm the certificate and private-key permissions separately. Do not disable CA validation or substitute a guessed certificate just to make an office network connect.

Done means

  • The installed interface name and wpa_supplicant version were checked.
  • The configuration contains the correct SSID and security mode and is readable only by its intended users.
  • A foreground test associated with the expected access point before background mode was used.
  • Address management was verified separately from WPA authentication.
  • No debug output exposed keys, and no broad process kill interrupted another interface.